Sign inSign up
Forklift API

dhi.io/forklift-api

Forklift API 2.x (fips, dev)

CIS
FIPS
STIG
linux/amd64
debian 13
Tags:

2-debian-fips-dev, 2-debian13-fips-dev, 2-fips-dev, 2.12-debian-fips-dev, 2.12-debian13-fips-dev, 2.12-fips-dev, 2.12.9-debian-fips-dev, 2.12.9-debian13-fips-dev, 2.12.9-fips-dev

Index digest:

sha256:570a6ae0c15780e35e6e6bf054282c643b60c5f9c1ef9f3d6c63703d15e9da46

Manifest digest:

sha256:37ccd26bf5c72a42d97c5b4fa8a8aed5e4e99ce4bfce233037cdc2e298d92d31

Size

67.07 MB

Last pushed

58 minutes ago

Vulnerabilities

0
0
0
1
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/forklift-api:2-debian-fips-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/forklift-api:2-debian-fips-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/forklift-api@sha256:dc2629f077bdb3da8b6f582232c98fa187133480de7bfafa4f60a167904caf1b
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/forklift-api@sha256:60af2a3bb3dd83eded9ac03174a0607145d7a4597f10e93420ad57e24d4cfcbc
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/forklift-api@sha256:6fa8e2fe9af9dcde33813d40a38916d660f0e703af220bf0eb72d1ec210adf97
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/forklift-api@sha256:c1ff184aae1228f25dbfe4c21b4436e6089ca2b9821204860811843ee49eda9f
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/forklift-api@sha256:abc3727238ba8d4031a6b6a1cf770d11acf7f20d59777e4a39819e7fad48d8da
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/forklift-api@sha256:b58eeac5b86f70d266680291995c06b83dbb798376c44ddc8e714b48ca3e95ac
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/forklift-api@sha256:2b3ffc4f559b425a30b15b032a90bb3ee3464b6c187b62853e42a8e04db4fa83
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/forklift-api@sha256:64c7fdb961a2d57d15baff6250333ce6cb792811827cd24ebd6c13c11fb4f302
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/forklift-api@sha256:47834c283a5976269149281ed02a721a90e453d8e0602445747b11038f6099e2
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/forklift-api@sha256:ea74da6fa9ce52bd3770ee51f8bd4a540bbfafe8d4df81cd111757f16084175c
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/forklift-api@sha256:a7d21857e0d2b39f41d4e1a2b429eab49d30ff9bfb0798146ff7a7f7f3eafd30
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/forklift-api@sha256:a965b20b90df5e8f247d4ee46b0b58d67ca37774b33cc4a6a1297334f8c4b548
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/forklift-api@sha256:2191787b4afa7dd39476b739f24c808360826a5d71f717839dfe7544e6316c28
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/forklift-api@sha256:6193d0842bdfcac04acda54027310d6c514737c722d7fd523c2d808cc0ac4acd
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/forklift-api@sha256:01563922d65ea2025e25bab01136c4c0b20ef95b401292fe58fa2043294cd325
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/forklift-api@sha256:15feda9f985a6bc88f58ca8a02c9c27d3fdf8aba8be261e069088316d16eac08
SPDX SBOMhttps://spdx.dev/Documentdhi.io/forklift-api@sha256:bc3c213a04466b31a7e3d614aa3fa3d86150be53b9acc65096150a0bc10eaceb